Skip to main content
posix86749
New Member
October 8, 2020
Question

FortiGate: Log filter in GUI

  • October 8, 2020
  • 3 replies
  • 5098 views

Hi, All

I Have Fortigate v6.0.5 build0268 (GA) (Virtual Appliance). And I have some problem with Forward Traffic log displaing.

I need to display events with particular address in destination field. For it I choose "destination" in filter and type in "somesite.com" (without quotes), but the list still shows all messages. It looks like filter not working. The same thing happens, when i choose "destination server" in filter options. 

What i'm doing wrong? What I need to do, to display events with particular address in destination field?

    3 replies

    Toshi_Esumi
    SuperUser
    SuperUser
    October 8, 2020

    Destination filter takes only IP. If you open the log detail, you wouldn't see "somesite.com" in the log, even you might be seeing in the table under Destination column in parentheses. Either convert the URL to IP then use it for Destination filter or user something else like Application, which shows up in the log detail.

    posix86749
    New Member
    October 9, 2020

    Thanks gro your answer. 

    But how can I filter log display if I need to show for wildcard destination address? For example, I need events, where in destination field there are present *microsoft.com, or *somesite*? Is it possible?

    Toshi_Esumi
    SuperUser
    SuperUser
    October 9, 2020

    You can open a ticket at TAC to get a definitive answer. But I'm 90% sure you can't at least with the current GUI software because I believe the filters are simply filtering/matching log content literary with the "keys" you put in.  

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.